Vulnerability Scanning Solutions, LLC.
Home
Our Process
Residential
Corporate
What We Scan For
Sample Report
Client List
Terms
Contact Us
What We Scan For
Family: Ubuntu Local Security Checks --> Category: infos

USN71-1 : postgresql vulnerability Vulnerability Scan


Vulnerability Scan Summary
postgresql vulnerability

Detailed Explanation for this Vulnerability Test

Synopsis :

These remote packages are missing security patches :
- libecpg-dev
- libecpg4
- libpgtcl
- libpgtcl-dev
- libpq3
- postgresql
- postgresql-client
- postgresql-contrib
- postgresql-dev
- postgresql-doc


Description :

John Heasman discovered a local privilege escalation in the PostgreSQL
server. Any user could use the LOAD extension to load any shared
library into the PostgreSQL server
the library's initialisation
function was then executed with the permissions of the server.

Now the use of LOAD is restricted to the database superuser (usually
'postgres').

Note: Since there is no way for normal database users to create
arbitrary files, this vulnerability is not exploitable remotely, e. g.
by uploading a shared library in the form of a Binary Large Object
(BLOB) to a public web server.

Solution :

Upgrade to :
- libecpg-dev-7.4.5-3ubuntu0.2 (Ubuntu 4.10)
- libecpg4-7.4.5-3ubuntu0.2 (Ubuntu 4.10)
- libpgtcl-7.4.5-3ubuntu0.2 (Ubuntu 4.10)
- libpgtcl-dev-7.4.5-3ubuntu0.2 (Ubuntu 4.10)
- libpq3-7.4.5-3ubuntu0.2 (Ubuntu 4.10)
- postgresql-7.4.5-3ubuntu0.2 (Ubuntu 4.10)
- postgresql-client-7.4.5-3ubuntu0.2 (Ubuntu 4.10)
- postgresql-contrib-7.4.5-3ubuntu0.2 (Ubuntu 4.10)
- postgresql-dev-7.4.5-3ubuntu0.2 (Ubuntu 4.10)
- postgresql-doc-7.4.5-3ubuntu0.2 (Ubuntu 4.10)



Threat Level: High


Click HERE for more information and discussions on this network vulnerability scan.

VSS, LLC.

P.O. Box 827051

Pembroke Pines, FL 33082-7051

Vulnerability Scanning Solutions, LLC.